SAP Knowledge Base Article - Preview

3677890 - "Peer certificate rejected by ChainVerifier" exception raised from SAP Cloud Connector

Symptom

Upon setting up a new HTTPS connection, that requires SSL certificate for trust between SCC and a backend system, following error is perceived from SCC trace (ljs_trace.log / scc_core.trc).


====
20xx-xx-xx xx:xx:xx,xxx -0400#INFO#com.sap.scc.rt#AccessControl connection checker#          #SccEndpointValidator failed to establish connection to HTTPS://backend-hostname-AAA:44300
iaik.security.ssl.SSLCertificateException: Peer certificate rejected by ChainVerifier
    at iaik.security.ssl.y.a(SourceFile:932)
    at iaik.security.ssl.n.b(SourceFile:1066)
    at iaik.security.ssl.n.a(SourceFile:1503)
    at iaik.security.ssl.y.d(SourceFile:784)
    at iaik.security.ssl.SSLTransport.startHandshake(SourceFile:569) 
====


Checking further, it was confirmed that certificate trusting hostname "backend-hostname-AAA" is maintained at SCC end and from backend system STRUST -> "SSL Client Standard", as per screenshot below.


Read more...

Environment

  • SAP Cloud Connector(SCC) release independent;
  • SAP Netweaver AS ABAP backend system.

Product

CONNECTOR FRAMEWORK all versions

Keywords

sap cloud connector, SCC, CC, connector, certificate, CA, certificate authority, HTTPS, SSL, TLS, iaik.security.ssl.SSLCertificateException, SccEndpointValidator,  , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , BC-SEC-SSF , Secure Store and Forward , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.